NA - CVE-2025-2745 - A cross-site scripting vulnerability exists in...
A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations...
NA - CVE-2025-36539 - AVEVA PI Data Archive products
are vulnerable...
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting...
NA - CVE-2025-44019 - AVEVA PI Data Archive products are vulnerable...
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting...
NA - CVE-2025-48699 - Rejected reason: DO NOT USE THIS CANDIDATE...
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
NA - CVE-2025-4417 - A cross-site scripting vulnerability exists in...
A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local access to the...
NA - CVE-2025-4418 - An improper validation of integrity check value...
An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow a miscreant with elevated...
NA - CVE-2025-5484 - A username and password are required to...
A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default...
NA - CVE-2025-5485 - User names used to access the web management...
User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential...
NA - CVE-2025-6031 - Amazon Cloud Cam is a home security camera that...
Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. When a user powers on the Amazon Cloud Cam, the device...
NA - CVE-2025-27689 - Dell iDRAC Tools, version(s) prior to 11.3.0.0,...
Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability,...